VulnCheck

First CVE: Apr 19, 2023Active for: 3 years
4,980
CVEs Published
More CVEs Published than 96% of tracked CNAs
1245.0
Avg CVEs / Year
More Avg CVEs / Year than 99% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 65% of tracked CNAs
0.4%
In CISA KEV
Higher KEV Rate than 83% of tracked CNAs

Trends Over Time

The number and severity of CVEs published by VulnCheck over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 19, 2023
3 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by VulnCheck as a CNA, regardless of affected vendor or product.

4,980 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the
Apr 29, 20269.899YESYES
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to e
Apr 7, 20259.899YESYES
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to exe
May 31, 20249.899YESYES
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the Sm
Jan 23, 20269.898YESYES
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous
Jan 22, 20269.898YESYES
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vu
Apr 22, 202510.098YESYES
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP reques
Nov 26, 20249.898YESYES
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_
Dec 5, 20258.897YESYES
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. A
Mar 24, 20259.897YESYES
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative
May 21, 20257.596YESYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA4,980 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCriticalUnknown
Attack Vector
Local875 (17.6%)
Network4,035 (81.0%)
Unknown8 (0.2%)
Physical10 (0.2%)
Adjacent Network44 (0.9%)
Attack Complexity
Low4,788 (96.1%)
High184 (3.7%)
Unknown8 (0.2%)
User Interaction
None3,944 (79.2%)
Unknown8 (0.2%)
Required936 (18.8%)
Privileges Required
Low1,803 (36.2%)
High143 (2.9%)
None3,026 (60.8%)
Unknown8 (0.2%)

Exploit Exposure

Signals from CVEs in this cna scope (4980 CVEs).

CISA KEV
19 CVEs
0.4% of CVEs· 83rd percentile
Metasploit
244 CVEs
4.9% of CVEs· 96th percentile
Nuclei
68 CVEs
1.4% of CVEs· 82nd percentile
ExploitDB
13 CVEs
0.3% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by VulnCheck as a CNA.

Media Mentions

Media articles that mention a CVE ID published by VulnCheck as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs